Showing posts with label McAfee. Show all posts
Showing posts with label McAfee. Show all posts

Tuesday, December 17, 2019

McAfee joins with Google Cloud to integrate McAfee Security offerings with GCP for Linux and Windows workloads, containers

McAfee and Google Cloud entered into an alliance to integrate key McAfee solutions for endpoint and container security within Google Cloud. Under this new partnership, McAfee will tightly integrate its endpoint security solutions for Linux and Windows workloads, as well as its MVISION Cloud solution for container security, on Google Cloud infrastructure.

Several enterprise customers leverage virtual machines (VMs) running in the cloud to handle key Linux and Windows workloads. Ensuring security of these workloads is critical. With this new integration, customers will be able to deploy McAfee’s advanced endpoint security solutions across these key workloads and VMs via Google Cloud Marketplace.


McAfee’s workload security technology uses advanced machine learning and cloud analytics to help protect against file-based, fileless, and script-based threats at scale for workloads deployed on Google Cloud.

Google Cloud provides organizations with critical infrastructure, platform capabilities and solutions, along with expertise, to reinvent their business with data-powered innovation on modern computing infrastructure. The Mountain View, California-based company delivers enterprise-grade cloud solutions that leverage Google technology to help companies operate more efficiently, modernize for growth and innovate for the future. Customers in more than 150 countries turn to Google Cloud as their trusted partner to solve critical business problems.  

McAfee is the device-to-cloud cybersecurity company. Inspired by the power of working together, McAfee creates business and consumer solutions that make the world a safer place. 


McAfee MVISION Cloud for Containers service extends data security, threat prevention, governance, and compliance capabilities of the MVISION Cloud platform to provide additional security for container-based workloads on Google Cloud. Organizations can also leverage MVISION to integrate security into DevOps processes and toolsets to discover and address security issues before applications are deployed.

“Increasingly, customers are choosing to move critical workloads and applications to the cloud because of the strong security protections it can provide,” said Anand Ramanathan, vice president of product and marketing at McAfee. “As more of these enterprises choose to leverage Google Cloud’s hyperscale capabilities, we’re excited to integrate our core capabilities in VM and container security to ensure Google Cloud customers can benefit from the highest levels of data protection and threat prevention.”

“We’re excited to partner with McAfee to bring their proven, trusted security capabilities to enterprise customers,” said Kevin Ichhpurani, corporate vice president, Global Ecosystem at Google Cloud. “Integrating McAfee’s solutions into Google Cloud means customers will have even more tools to ensure the highest levels of data security and protections as they migrate mission-critical workloads to the cloud.”

Wednesday, December 11, 2019

McAfee releases CASB-integrated cloud security platform for container-based applications

McAfee announced McAfee MVISION Cloud for Containers that integrates container security with its Cloud Access Security Broker (CASB) and Cloud Security Posture Management (CSPM) security solution. 

Leveraging NanoSec’s zero trust application visibility and control capabilities for container-based deployments in cloud environments, the solution provides customers with the ability to speed up application delivery, while enhancing the governance, compliance and security of their container workloads.




The acquisition of NanoSec will strengthen the container security capabilities of McAfee MVISION Cloud and MVISION Server Protection products, giving its customers the ability to speed up application delivery while enhancing governance, compliance and security of their hybrid, multi-cloud deployments. 

NanoSec’s security capabilities will be applied to applications and workloads deployed in containers and Kubernetes and will be integrated into McAfee MVISION Cloud and MVISION Server Protection offerings. These capabilities include continuous configuration compliance and vulnerability assessment as well as runtime application-level segmentation for detecting and preventing lateral movement of threats.


Container security has long been treated as separate from other Infrastructure as a Service (IaaS) security solutions, requiring evaluation, investment and management of multiple, niche products thus increasing total cost of ownership and complexity and reducing security. 

McAfee MVISION Cloud for Containers integrates Cloud Security Posture Management (CSPM) and Vulnerability Scanning for container workloads into the existing McAfee MVISION Cloud platform to give customers a unified cloud security solution where consistent security policies can be implemented across all forms of cloud IaaS workloads.

McAfee MVISION Cloud integrates with DevOps tools, helps users “shift-left” to pre-emptively improve compliance and secure container workloads by running security audits in the DevOps pipeline and providing security incident data directly back to the development teams. 

Additionally, McAfee MVISION Cloud also continuously monitors the production deployments of these container workloads to ensure configuration drift does not compromise the security of the applications.


Currently available, McAfee MVISION Cloud for Containers provides CSPM that integrates Configuration Audit checks for containerized workloads to ensure the container platforms run in accordance with CIS and other best practice compliance standards. This is designed to ensure security checks for the complete container stack including the configuration of the virtual machine the container runs on, as well as the storage, network and other Platform as a Service (PaaS) services the container may be accessing.

The offering also adds vulnerability scanning of container images that helps to identify and prevent the use of weak or exploitable components of the container images. This reduces the overall risk profile of the application by minimizing the attack vectors. With Shift Left DevOps integration, users can perform CSPM and Vulnerability Scanning checks earlier in the application development lifecycle. This helps identify risk and provide meaningful feedback to developers within the build process. Additionally, continuously monitor and prevent configuration drift on production deployments of the container workloads.

Tuesday, December 10, 2019

McAfee aligns with Amazon Web Services to bring MVISION Cloud support to Amazon Detective

McAfee has announced that McAfee MVISION Cloud for Amazon Web Services (AWS) now includes support for Amazon Detective, providing customers with seamless incident detection and remediation. Through the integration of MVISION Cloud with Amazon Detective, customers have the ability to react to security issues quickly and confidently while leveraging the appropriate tools for incident investigation. 


Amazon Detective is a security service that is designed to easily analyze, investigate, and quickly identify the root cause of security findings or suspicious activities. Amazon Detective automatically collects log data from AWS resources and uses machine learning, statistical analysis, and graph theory to help customers visualize and conduct faster and more efficient security investigations. 

With McAfee MVISION Cloud, AWS customers can leverage a trusted cloud platform that has achieved AWS Security Competency status as well as AWS Well-Architected Partner designation for its Cloud Access Security Broker (CASB) technology to help locate issues and threats, and move without friction into the analysis phase to resolve the risk.


The capabilities in McAfee MVISION Cloud for AWS include integration with Amazon Detective to detect configuration issues or other cloud risks using McAfee MVISION Cloud and move seamlessly into the investigation phase with Amazon Detective.


The offering comes with architectural freedom of choice that includes Configuration Audit / Cloud Security Posture Management (CSPM) for diverse cloud workloads. Incidents can be detected for a wide array of virtual machine (Amazon Elastic Compute Cloud (Amazon EC2)) or container-based workloads (Amazon Elastic Container Service (Amazon ECS), and Amazon Elastic Kubernetes Service (Amazon EKS) including storage services needed to support the target applications.

Its rich, multifaceted incident data provides integrated CASB-derived functionality such as DLP / Malware detection and user behavior and threat analytics that go beyond detecting basic configuration issues. Identify threats and prioritize remediation, for a frictionless move into Amazon Detective to resolve risks quickly and efficiently.

“We worked closely with AWS to integrate a solution that our mutual customers can use to get total visibility and control over their applications and workloads on AWS,” said Rajiv Gupta, senior vice president of Cloud Security, McAfee. “McAfee MVISION Cloud complements Amazon Detective’s capabilities by using a frictionless, API-based, cloud-native approach that allows security professionals to seamlessly enforce data loss prevention, avoid unauthorized sharing of data, address threats from insiders and compromised accounts, prevent misconfiguration drift, audit all user activity and secure corporate data as organizations leverage the cloud to accelerate their business.”


“McAfee’s market-leading Cloud Security Platform provides a uniform approach to protecting data and stopping threats in the cloud through comprehensive and consistent policies,” said Nemi George, vice president, information security officer, Pacific Dental Services. “The new Amazon Detective integration will give us the added investigation capabilities to improve our compliance and reduce the risk within our cloud infrastructure.”

“We’re delighted that McAfee MVISON Cloud on AWS now supports Amazon Detective, providing enterprises the ability to continue their journey to the cloud with an additional layer of security,” said Dan Plastina, vice president of ESS Security Services, Amazon Web Services. “Customers using Amazon Detective will now be able to automate time-consuming tasks so they are free to focus on the performance, availability, and compatibility of their applications.”

Saturday, November 9, 2019

McAfee MVISION Cloud is now a certified Data Loss Prevention provider for Microsoft Teams

McAfee announced that its cloud access security broker (CASB) technology is now Certified for Microsoft Teams. McAfee MVISION Cloud is now Certified for Microsoft Teams to serve the needs of partners and customers with a unified, cloud-native security platform that consistently protects their data and defends against threats in the cloud.

Teams is a chat-based workspace in Office 365 that brings together people, conversations and content—along with the tools that teams need—so they can easily collaborate to achieve more. It’s integrated with the familiar Office applications and is built from the ground up on Office 365. Since its debut on the market just a little over two years ago, Teams has quickly took a hold on the market with over 13 million active daily users. 


With McAfee MVISION Cloud for Microsoft Teams, companies can answer employees’ requests for a collaboration platform, while enforcing the security capabilities they need to keep data safe.

With McAfee MVISION Cloud, organizations can enforce sensitive data policies: prevent sensitive data that cannot be stored in the cloud from being uploaded to Teams; build sharing and collaboration guardrails: prevent sharing of sensitive or regulated data with unauthorized parties in Teams; and limit activities for users on unmanaged devices and untrusted networks: gain control over user access to Teams by enforcing context-specific policies limiting end-user actions.


The platform can also perform forensic investigations with full context: capture a complete audit trail of all user activity enriched with threat intelligence to facilitate post- incident forensic investigations. It can detect and correct user threats and malware: detect threats from compromised accounts, insider threats, privileged access misuse, and malware infection.

Teams is the hub for teamwork in Microsoft 365 that brings together people, conversations and content—along with the tools that teams need—so they can easily collaborate to achieve more. It’s integrated with the familiar Microsoft Office 365 applications and is built from the ground up on the Office 365, secure cloud. 

With McAfee MVISION Cloud for Microsoft Teams, companies can answer employees’ requests for a collaboration platform, while enforcing the security capabilities they need to keep data safe.

The offering will leverage McAfee’s content analytics engine to discover sensitive data uploaded to Microsoft Teams based on keywords and phrases indicative of sensitive or regulated information; pre-defined alpha-numeric patterns with validation such as credit card numbers; regular expressions to detect custom alpha-numeric patterns like part numbers; file metadata such as file name, size, and file type; fingerprints of unstructured files with exact and partial or derivative match; fingerprints of structured databases or other structured data files; and keyword dictionaries of industry-specific terms such as stock symbols.


“We worked to develop a solution that our customers can use to get visibility and control over their data and user activity in Microsoft Teams,” said Rajiv Gupta, senior vice president of Cloud Security, McAfee. “McAfee MVISION Cloud complements Microsoft Teams’ capabilities by using a frictionless, API-based, cloud-native approach that allows security professionals to provide data loss prevention, collaboration control, and contextual access control policies, address threats from insiders and compromised accounts, audit all user activity and secure corporate data as users collaborate in the cloud.”

“We’re pleased to see McAfee’s commitment to supporting and securing this ever-increasing demand,” said Levon Esibov, Partner PM Director, Information Protection, Microsoft Teams at Microsoft said. “McAfee MVISION Cloud integrates with Microsoft Teams APIs—ensuring our joint customers can successfully meet key security and compliance requirements.”

Thursday, November 7, 2019

McAfee MVISION Cloud offers “Shift Left” with security to boost compliance and reduce risk on Microsoft Azure

McAfee announced updates to McAfee MVISION Cloud for Microsoft Azure that will help customers “Shift Left” with security to preemptively help to address compliance and risk within their cloud infrastructure. 

With McAfee MVISION Cloud, security is pushed earlier into the DevOps process so that security professionals can catch risky configurations before they become a threat in production. This gives organizations the ability to deploy applications in the cloud with greater speed and efficiency. 


While Infrastructure-as-a-Service (IaaS) and Platform-as-a-Service (PaaS) environments provide customers with choice and flexibility, if not configured correctly, they also potentially increase the organization’s surface area for security risks. 




McAfee detects compromised account activity in Azure based on brute force login attempts, logins from new and untrusted locations for a specific user, and consecutive login attempts from two locations in a time period that implies impossible travel – even if the two logins occur across multiple cloud services – to support immediate remediation and limit exposure.


McAfee automatically constructs a behavior model with dynamic and continuously updated thresholds for each user and group to identify activity indicative of insider threat. Privileged user analytics identifies risk from inactive administrator accounts, excessive permissions, and unwarranted escalation of privileges and user provisioning.


McAfee MVISION Cloud for Azure enforces DLP policies across data at rest and in motion to ensure compliance with regulations and internal policies. McAfee supports DLP rules based on keywords, data identifiers, user groups, and regular expressions. Enforcement actions include coach users, notify administrator, block, quarantine, and delete. Leverage pre-built industry templates, create custom policies in McAfee, or leverage policies in an existing on-premises DLP solution.



With the new features in McAfee MVISION Cloud for Azure, security groups can integrate policy natively into DevOps processes and toolsets to discover security issues before systems are deployed to accelerate business in the cloud. 


New capabilities include security scans for Azure Resource Manager templates that allow users to discover risky configuration issues or violations in Azure Resource Manager Templates prior to deploying resources. Its inline integration with the tools developers use: security checks inside the DevOps pipeline through API integration with tools including Microsoft Git, Github, and Azure DevOps. Security Feedback is natively integrated into the build process saving time, effort, and frustration.



The offering also offers unified cloud security for Azure ecosystem to allows developers to leverage Azure services knowing security will be built-in by design (IaaS/PaaS/Container services) aligning closely to the Cloud Security Posture Management (CSPM) best practices. Its preemptive risk avoidance improves compliance with regulatory frameworks and reduces the likelihood of data loss, abuse or fines associated with improper security controls by highlighting security findings before they become security incidents.


The new “Shift Left” capabilities in McAfee MVISION Cloud for Microsoft Azure are available now.

Friday, October 25, 2019

McAfee uses Expert Rules in ENS 10.5.3 to prevent malicious exploits

Expert Rules are text-based custom rules that can be created in the Exploit Prevention policy in ENS Threat Prevention 10.5.3+. Expert Rules provide additional parameters and allow much more flexibility than the custom rules that can be created in the Access Protection policy. It also allows system administration to control / monitor an endpoint system at a very granular level. 

Expert rules do not rely on Use-Mode hooking; hence they have very minimal impact on a system’s performance. This blog post acts as a basic guide to show customers how to create them and which threats they can help block.

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...